[Dreamhack] Level 1: Cherry
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/959 CherryDescription ์ฃผ์–ด์ง„ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•˜์—ฌ ์ต์Šคํ”Œ๋กœ์ž‡ํ•˜๊ณ  ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”! ํ”Œ๋ž˜๊ทธ๋Š” flag.txt ํŒŒ์ผ์— ์žˆ์Šต๋‹ˆ๋‹ค. ํ”Œ๋ž˜๊ทธ์˜ ํ˜•์‹์€ DH{...} ์ž…๋‹ˆ๋‹ค.dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ •(1) ํŒŒ์ผ ๋ถ„์„  ์ผ๋‹จ ํ•ด๋‹น ๋ฐ”์ด๋„ˆ๋ฆฌ ํŒŒ์ผ์€ gcc -fno-stack-protector -no-pie chall.c -o chall ๋กœ ์ปดํŒŒ์ผ ๋˜์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ฃผ์†Œ๊ฐ€ ๊ณ ์ •๋˜์–ด์žˆ๋‹ค. // Compile: gcc -fno-stack-protector -no-pie chall.c -o chall๋ฐ”์ด๋„ˆ๋ฆฌ ํŒŒ์ผ์„ ์‹คํ–‰ํ•ด๋ณด๋ฉด ๋‘ ๋ฒˆ์˜ ์ž…๋ ฅ์„ ๋ฐ›๊ฒŒ ๋œ๋‹ค. initialize(): ๋ฒ„ํผ๋ง์„ ๋น„ํ™œ์„ฑํ™”ํ•˜๊ณ , S..
[Dreamhack] Level 1: Return Address Overwrite
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/351/ Return Address OverwriteDescription Exploit Tech: Return Address Overwrite์—์„œ ์‹ค์Šตํ•˜๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.dreamhack.io๋“œ๋ฆผํ•ต ๊ฐ•์˜ https://learn.dreamhack.io/58  ๋ฅผ ๋ณด๋ฉด์„œ ํ’€์ดํ•˜์˜€์Šต๋‹ˆ๋‹ค.  2. ํ•ด๊ฒฐ ๊ณผ์ •(1) ์ฝ”๋“œ ํ™•์ธ ๋จผ์ € ์ž…๋ ฅ ๊ธธ์ด์— ๋Œ€ํ•œ ๊ฒ€์ฆ์ด ์—†๋Š” scanf๋ฅผ ์“ฐ๊ณ  ์žˆ์œผ๋ฏ€๋กœ, ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ ์ทจ์•ฝ์ ์ด ์กด์žฌํ•œ๋‹ค๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.scanfํ•จ์ˆ˜์˜ ํฌ๋งท ์ŠคํŠธ๋ง ์ค‘ ํ•˜๋‚˜์ธ %s๋Š” ๋ฌธ์ž์—ด์„ ์ž…๋ ฅ๋ฐ›์„ ๋•Œ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์œผ๋กœ, ์ž…๋ ฅ์˜ ๊ธธ์ด๋ฅผ ์ œํ•œํ•˜์ง€ ์•Š์œผ๋ฉฐ, ๊ณต๋ฐฑ ๋ฌธ์ž์ธ ๋„์–ด์“ฐ๊ธฐ, ํƒญ, ๊ฐœํ–‰ ๋ฌธ์ž ๋“ฑ์ด ๋“ค์–ด์˜ฌ ๋•Œ๊นŒ์ง€ ๊ณ„์† ์ž…๋ ฅ์„ ๋ฐ›๋Š”..
[Dreamhack] Level 1: basic_exploitation_001
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/3 basic_exploitation_001Description ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์—์„œ ์ž‘๋™ํ•˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค(basic_exploitation_001)์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์ ์„ ์ฐพ๊ณ  ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด "flag" ํŒŒ์ผ์„ ์ฝ์œผ์„ธ์š”. "flag" ํŒŒ์ผ์˜ ๋‚ด์šฉdreamhack.io ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์—์„œ ์ž‘๋™ํ•˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค(basic_exploitation_001)์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค.ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์ ์„ ์ฐพ๊ณ  ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด "flag" ํŒŒ์ผ์„ ์ฝ์œผ์„ธ์š”."flag" ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ์›Œ๊ฒŒ์ž„ ์‚ฌ์ดํŠธ์— ์ธ์ฆํ•˜๋ฉด ์ ์ˆ˜๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.ํ”Œ๋ž˜๊ทธ์˜ ํ˜•์‹์€ DH{...} ์ž…๋‹ˆ๋‹ค.2. ํ•ด๊ฒฐ ๊ณผ์ •(1) ๋ฌธ์ œ ๋ถ„..
[Dreamhack] Beginner: shell_basic
ยท
CTF, War game
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[Dreamhack] beginner: bof
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/1111 bofDescription Buffer overflow is one of the basics of pwnable ๐Ÿฑ The path of the flag file is /home/bof/flag.dreamhack.ioThe path of the flag file is /home/bof/flag.2. ํ’€์ด(1) ์ฝ”๋“œ ํ™•์ธmain(): ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ์„ ๋ฐ›์•„ read_cat()ํ•จ์ˆ˜๋ฅผ ํ˜ธ์ถœํ•˜๊ณ  ์ž…๋ ฅ์„ ์ถœ๋ ฅํ•˜๋Š” ์ฝ”๋“œ์ด๋‹ค. ์ด๋•Œ ./cat ์ด ์ €์žฅ๋˜๋Š” v5๋ณ€์ˆ˜๋Š” 16๋ฐ”์ดํŠธ์ด๊ณ , ์ž…๋ ฅ๊ฐ’์€ 128 ๋ฐ”์ดํŠธ์˜ ํฌ๊ธฐ์ด๋‹ค. ์ฆ‰,  v4์˜ ํฌ๊ธฐ๊ฐ€ 128๋ฐ”์ดํŠธ์ธ๋ฐ, scanf๋กœ ์ตœ๋Œ€ 144๋ฐ”์ดํŠธ๋ฅผ ์ฝ์–ด๋“ค์ด๋ฏ€๋กœ, bof๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ..
[Dreamhack] beginner: baby-bof
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/974 baby-bofDescription Simple pwnable 101 challenge Q. What is Return Address? Q. Explain that why BOF is dangerous.dreamhack.io Q. What is Return Address?Q. Explain that why BOF is dangerous.2. ํ’€์ด๋ฌธ์ œ์— ๋‘๊ฐ€์ง€ ์งˆ๋ฌธ์ด ์ œ์‹œ๋˜์–ด ์žˆ์œผ๋ฏ€๋กœ, ์ด ์งˆ๋ฌธ์— ๋Œ€ํ•œ ๋‹ต์„ ํ•ด๊ฒฐํ•˜๋ฉด์„œ ๋ฌธ์ œ๋ฅผ ํ’€์–ด๋ณผ ๊ฒƒ์ด๋‹ค. ๋จผ์ € ๋ฌธ์ œ ์‹คํ–‰ํŒŒ์ผ์„ ida๋ฅผ ํ†ตํ•ด ๋””์Šค์–ด์…ˆ๋ธ” ํ•ด๋ณด๋ฉด, ์•„๋ž˜์™€ ๊ฐ™์€ ์ฝ”๋“œ๊ฐ€ ๋ณด์—ฌ์ง„๋‹ค.  the main function doesn't call win function (0x4012..
mnzy๐ŸŒฑ
-->